CVE-2025-47914Out-of-bounds Read in X Crypto Golang.org X Crypto SSH Agent

CWE-125Out-of-bounds Read9 documents7 sources
Severity
5.3MEDIUMNVD
EPSS
0.0%
top 94.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19

Description

SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

Patches

🔴Vulnerability Details

5
CVEList
Malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agent2025-11-19
GHSA
golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read2025-11-19
OSV
CVE-2025-47914: SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is m2025-11-19
OSV
Malformed constraint may cause denial of service in golang.org/x/crypto/ssh/agent2025-11-19
OSV
golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read2025-11-19

📋Vendor Advisories

2
Red Hat
golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages2025-11-19
Debian
CVE-2025-47914: golang-go.crypto - SSH Agent servers do not validate the size of messages when processing new ident...2025

💬Community

1
Bugzilla
CVE-2025-47914 golang.org/x/crypto/ssh/agent: SSH Agent servers: Denial of Service due to malformed messages2025-11-19
CVE-2025-47914 — Out-of-bounds Read | cvebase